About the IAM role in cdk bootstrap

Viewed 1406

The following IAM roles were found in the bootstrap of cdk.

  • FilePublishingRole
  • ImagePublishingRole
  • LookupRole
  • DeploymentActionRole
  • CloudFormationExecutionRole

I understand the meaning of CloudFormationExecutionRole, but in what situations are the other IAM roles used? I would like to know if there is any documentation that clearly states this.

2 Answers

The roles are defined here. Looking at the definitions you can see what they are used for:

  • FilePublishingRole - access to S3 with associated KMS
  • ImagePublishingRole - access to ECR
  • LookupRole - role to performe lookups with various fromLookup methods
  • DeploymentActionRole - access to CloudFormation, KMS and S3

As per official documentation:

  • FilePublishingRole, ImagePublishingRole - are assumed by the AWS CDK Toolkit and by AWS CodeBuild projects to publish assets into an environment: that is, to write to the S3 bucket and the ECR repository, respectively. These roles require write access to these resources.
  • LookupRole - is assumed by the AWS CDK Toolkit to perform context lookups in an environment. Its AssumeRolePolicy controls who can deploy into the environment.
  • DeploymentActionRole - is assumed by the AWS CDK Toolkit and by AWS CodePipeline to deploy into an environment. Its AssumeRolePolicy controls who can deploy into the environment.
Related